logo

Supply Chain Attack Compromises 143 Mastra npm Packages with Malicious Dependency

ID: 299455e9-7d2b-5f99-ae9a-8ebcb02b36aa

STIX ID: report--299455e9-7d2b-5f99-ae9a-8ebcb02b36aa

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

...
...

On June 17, 2026 an attacker hijacked a former maintainer account to republish 143 packages in the @mastra npm scope, injecting a malicious dependency called easy-day-js that masquerades as dayjs, disables TLS verification in a postinstall hook, and downloads a cryptocurrency stealer; widely used packages (including @mastra/core with ~4 million monthly downloads) were affected, and users who installed any affected packages after June 17 should consider systems compromised and remediate immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.